AZ-104 Manage Azure Identities and Governance Practice Question
Exhibit
Policy design notes: - Scope: subscription - Target: all resource groups - Desired outcome: add tag CostCenter=042 automatically - Requirement: do not block the deployment if the tag is omitted Policy effects being considered: - Deny - Audit - Append - Modify
Based on the exhibit, a subscription policy must add CostCenter=042 to new resources, and deployments must not fail if the tag is missing. Which policy effect should you use?
⚠ Common exam trap
The trap is that candidates often choose 'Append' because it can add tags, but 'Modify' is the recommended effect for tag management. 'Modify' supports conflict resolution settings such as 'conflictEffect', which can be set to 'audit' to avoid deployment failures when the tag is missing. 'Append' is not deprecated, but it does not provide the same conflict-handling flexibility for tag updates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify
The 'Modify' effect (option D) is correct because it can add the CostCenter=042 tag to new resources without causing deployment failures if the tag is missing. Unlike 'Deny', which blocks non-compliant resources, 'Modify' uses a 'merge' operation to add tags during resource creation or update, and its 'conflictEffect' can be set to 'audit' to allow deployments to succeed. 'Append' is not deprecated and can also add tags, but 'Modify' is the recommended effect for tag management because it supports conflict resolution and can update existing tags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deny
Why it's wrong here
Deny would block the deployment instead of allowing it to continue when the tag is missing.
When this WOULD be correct
Use Deny when you need to enforce that all new resources must have a specific tag, and you want to block creation of any resource that doesn't comply (e.g., to ensure cost tracking).
- ✗
Audit
Why it's wrong here
Audit only records non-compliance and does not automatically add the missing tag.
When this WOULD be correct
Use Audit when you need to evaluate compliance of existing resources or deployments without blocking them, such as when testing a new policy before enforcing it, or when you only need to report on non-compliance without automatic remediation.
- ✗
Append
Why it's wrong here
Append can add properties in some request scenarios, but it is not the best choice for automatic tag correction behavior.
When this WOULD be correct
Append would be correct if the policy needed to add a tag only to resources that lack it entirely, without modifying existing tags. For example, 'Add tag Environment=Production to all new resources that do not already have an Environment tag'.
- ✓
Modify
Why this is correct
Modify is used to automatically change resource requests, such as adding or correcting tags, without blocking deployment.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓ModifyCorrect answer▾
Why this is correct
Modify is used to automatically change resource requests, such as adding or correcting tags, without blocking deployment.
✗DenyWrong answer — click to see why▾
Why this is wrong here
Deny prevents creation of resources that don't have the tag, but the requirement states deployments must not fail if the tag is missing.
★ When this WOULD be the correct answer
Use Deny when you need to enforce that all new resources must have a specific tag, and you want to block creation of any resource that doesn't comply (e.g., to ensure cost tracking).
Why candidates choose this
Candidates may think Deny is the only way to enforce tagging, overlooking that Modify can add tags without blocking deployment.
✗AuditWrong answer — click to see why▾
Why this is wrong here
Audit only logs non-compliant resources without automatically adding the missing tag, so deployments would succeed but the tag would not be added, failing to meet the requirement to add CostCenter=042 to new resources.
★ When this WOULD be the correct answer
Use Audit when you need to evaluate compliance of existing resources or deployments without blocking them, such as when testing a new policy before enforcing it, or when you only need to report on non-compliance without automatic remediation.
Why candidates choose this
Candidates may think Audit is sufficient because it logs missing tags, but they overlook the requirement to automatically add the tag, assuming logging alone satisfies the policy goal.
✗AppendWrong answer — click to see why▾
Why this is wrong here
Append only adds the tag if it's missing but does not correct existing tags with different values; Modify can add or change the tag value. The question requires adding CostCenter=042, and Append would fail to update resources that already have a different CostCenter value.
★ When this WOULD be the correct answer
Append would be correct if the policy needed to add a tag only to resources that lack it entirely, without modifying existing tags. For example, 'Add tag Environment=Production to all new resources that do not already have an Environment tag'.
Why candidates choose this
Candidates may confuse Append with Modify, thinking Append can also change existing values, or they may overlook the requirement to handle resources with an existing different tag value.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Managed Identities for Azure Resources
Key term
Subscription
A subscription is a payment model where you pay a recurring fee to access a product or service instead of buying it once and owning it forever.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 1,053 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.